[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[bug#74060] [PATCH] gnu: Remove allegro-5.0. [security fixes]
From: |
Maxim Cournoyer |
Subject: |
[bug#74060] [PATCH] gnu: Remove allegro-5.0. [security fixes] |
Date: |
Mon, 11 Nov 2024 21:37:31 +0900 |
User-agent: |
Gnus/5.13 (Gnus v5.13) |
Hi!
Nicolas Graves <ngraves@ngraves.fr> writes:
> This package has no dependencies in Guix, is unsupported (see
> https://liballeg.org/old.html) and is vulnerable to CVE-2021-36489.
>
> * gnu/packages/game-development.scm (allegro-5.0): Delete variable.
> * gnu/local.mk: Deregister patch.
> * gnu/packages/patches/allegro-mesa-18.2.5-and-later.patch: Delete file.
We also have an allegro-4.0 variable; is this one not vulnerable?
https://nvd.nist.gov/vuln/detail/CVE-2021-36489 suggest it is (up to
5.2.6).
--
Thanks,
Maxim
- [bug#74060] [PATCH] gnu: Remove allegro-5.0. [security fixes],
Maxim Cournoyer <=